Forum Discussion
What is the dependency of Microsoft Purview with Intune Endpoint management portal?
Thank you for posting your question here!
As far as an Intune dependency, this only really comes into play when you want to leverage Endpoint DLP policies. Endpoint DLP policies can only be enforced on managed devices that are signed into with a user's company credentials. Check out the link below on Endpoint DLP requirements. With that said, Endpoint DLP runs through the Microsoft Defender service on the PC so there are no additional installs needed or anything, but the devices will need to run the same onboarding script/Intune policy as you would for Microsoft Defender for Endpoint. If you're running a third-party AV/EDR like CrowdStrike or something, you still need to onboard the device, but the Defender service will automatically run in Passive Mode on the endpoint and Endpoint DLP policies will be enforced, without disrupting the third-party service. Also, while the device needs to be a managed endpoint, Endpoint DLP policies are still scoped to identities, not devices, and will follow the user to any managed device they login to.
Get started with Endpoint data loss prevention | Microsoft Learn
Microsoft Purview DLP – Part 2 – Endpoint DLP – Cloudy Security (cloudy-sec.com)
For other DLP locations (Exchange, SharePoint, OneDrive, etc.) the dependency is based on the identity of the user and who is signed into the service or app (Word, Excel, PowerPoint, etc.). Same with Labels. As long as the user is signing in to the app or service with a set of company credentials that are assigned to a DLP or label policy, the policies will take effect and the labels will appear as normal.